urp3pf20jffqcgw.kagowi.ru

Maranta Services

Domain Information

The domain urp3pf20jffqcgw.kagowi.ru registered by Maranta Services was initially registered in July of 2014 through REGRU-REG-RIPN. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Amsterdam, Noord-Holland within Netherlands which resides on the RIPE Network Coordination Centre network.
Registrar:
REGRU-REG-RIPN

Server location:
Noord-Holland, Netherlands (NL)

Create date:
Monday, July 7, 2014

Expires date:
Tuesday, July 7, 2015

ASN:
AS59711 FORTUNIX-AS Fortunix Networks L.P.,GB

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

ESET NOD32
Win32/Hoax.ArchSMS.AHD.Gen application
100.00%

Emsisoft Anti-Malware
Gen:Variant.Graftor.139399, Application.Generic.678399, Application.Generic.679103
100.00%

Kaspersky
not-a-virus:Downloader.Win32.Monstruos, Trojan.Win32.Inject
66.67%

AVG
Adware Skodna.ArchSMS.CNG, Adware Skodna.ArchSMS.COD
66.67%

Norman
Application.Generic.678399, Application.Generic.679103
66.67%

Clam AntiVirus
Win.Trojan.Agent-730660
33.33%

MicroWorld eScan
Gen:Variant.Graftor.139399
33.33%

Malwarebytes
Trojan.SMSHoax
33.33%

Bitdefender
Gen:Variant.Graftor.139399
33.33%

Lavasoft Ad-Aware
Gen:Variant.Graftor.139399
33.33%

F-Secure
Gen:Variant.Graftor.139399
33.33%

G Data
Gen:Variant.Graftor.139399
33.33%

Vba32 AntiVirus
suspected of Malware-Cryptor.Win32.General
33.33%

IKARUS anti.virus
PUA.Win32.InstallMonstr
33.33%

F-Secure
Riskware.Application.Generic.679103
33.33%

The domain urp3pf20jffqcgw.kagowi.ru has been seen to resolve to the following IP address.

August 1, 2014

File downloads found at URLs served by urp3pf20jffqcgw.kagowi.ru.

URL:
http://urp3pf20jffqcgw.kagowi.ru/

Web server:
nginx/1.4.2 (PHP/5.4.17)